Junglewise Threat Intelligence

CVE-2026-3245: Canon PRISMAproduction deserialization remote code execution

CVE-2026-3245 · Severity: high · CVSS 7.5 · Published 2026-08-03

Vendors: Canon.

Executive brief

Canon PRISMAproduction is a production printing software platform used to manage and control large-format printing workflows. A deserialization flaw in version 6.5 and earlier allows an unauthenticated attacker on an adjacent network to execute arbitrary code, potentially gaining complete control over the printing system and any data it processes.

Technical details

The vulnerability is a deserialization flaw in PRISMAproduction that permits remote code execution. An unauthenticated attacker positioned on an adjacent network can exploit this weakness without requiring user interaction or special conditions (AC:H and UI:N per CVSS v3). The attack requires network adjacency (AV:A), suggesting the system must be on the same local network segment. Successful exploitation grants the attacker arbitrary code execution capabilities. A patch is available in version 6.5.1 and higher, requiring assistance from Canon Service & Support for installation.

Affected products

  • Canon PRISMAproduction 6.5 and earlier

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: patched: Fix available in version 6.5.1 or higher

References